2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26872HIGH8.8AMI Megarac Password reset interception via API
CVE-2022-38451HIGH7.5A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially craf...
CVE-2022-2988HIGH7.5A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a mali...
CVE-2022-46359HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46358HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46357HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46356HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-25967HIGH8.8Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine co...
CVE-2022-25936HIGH7.5Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the fi...
CVE-2022-48285HIGH7.3loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
CVE-2022-4205HIGH7.5In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.
CVE-2022-39812HIGH7.5Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthentica...
CVE-2022-48116HIGH7.2AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.in...
CVE-2022-4139HIGH7.8An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memor...
CVE-2022-48073HIGH7.5Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
CVE-2022-48072HIGH7.8Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the a...
CVE-2022-48071HIGH7.5Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
CVE-2022-48070HIGH7.8Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the...
CVE-2022-48069HIGH7.5Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.
CVE-2022-44715HIGH8.8Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions v...
CVE-2022-2712HIGH7.5In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not fi...
CVE-2022-45770HIGH7.8Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalat...
CVE-2022-44264HIGH7.8Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.
CVE-2022-44263HIGH7.8Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
CVE-2022-41029HIGH7.2Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUAR...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now